CVE Vulnerabilities

CVE-2007-2438

Published: May 02, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines.

Affected Software

NameVendorStart VersionEnd Version
Foresight_linuxForesight_linux1.1 (including)1.1 (including)
Red Hat Enterprise Linux 5RedHatvim-2:7.0.109-3.el5.3*
VimUbuntuedgy*
VimUbuntufeisty*

References